For nearly two years, one security researcher has been quietly watching North Korea’s hackers from the inside — and what he found is genuinely alarming. Greece-based researcher Vangelis Stykas, CTO at cybersecurity firm Kumio, says he maintained access to command-and-control servers used by a group of North Korean state-linked operators for 22 months. In that time he uncovered evidence that 1,640 companies across 57 countries were touched by the country’s hacking campaigns.
Stykas laid out his findings at the Black Hat security conference in Las Vegas. Of those 1,640 organizations, he estimates that around 700 to 800 suffered what he calls “really damaging” intrusions. And by damaging, he means total. “It’s company access, it’s root access to servers, it’s root access to AWS,” he told WIRED. “For crypto companies, it’s keys, it’s blockchain access — it’s ridiculous access.”
The delicious twist: in some cases the hackers appeared to have infected themselves with their own malware, handing Stykas a window straight onto their workstations. “I have access to their Slack, I have access to their Discord, I have access to a lot of stuff,” he says. In total he reviewed roughly 5 terabytes of data, sifting through developer keys, source code, and internal chatter to identify victims and warn them.
At Black Hat, Stykas publicly named around a dozen affected organizations — mostly the ones that handled his disclosures responsibly. The list is striking:
- Boston Children’s Hospital, which held a large Covid-19 database of Americans’ health data
- Japanese tech firm AEON Smart Technology
- Chinese phone maker Oppo
- Crypto firms Coinbase and Uniswap Labs
- Italy’s Supreme Judicial Council
- A subsidiary of Saudi Arabia’s Al Rajhi Bank
- Digitaal Vlaanderen, part of Belgium’s Flemish Government
The method behind it all is depressingly simple. In almost every case, the attackers used fake job offers dangling high salaries to lure software developers. The target would be asked to download a coding “test” that silently installed malware — a technique Microsoft has tracked since 2022 under the name Contagious Interview. External contractors made ideal targets: they often carried developer keys and access to many systems at once. “I have seen a couple of contractors that had access to up to 30 companies,” Stykas says.
Curiously, despite sitting on troves of sensitive data — one US company reportedly held vast access to Americans’ criminal records — the hackers stayed laser-focused on cryptocurrency wallets. That’s cold comfort, warns Expel researcher Marcus Hutchins, who notes that persistent access could easily be handed to an espionage team later. “All it would take is for one person to get given access to that system, and they could just go to town.”
The companies Stykas named are, in a sense, the lucky ones. The real worry is the hundreds that never replied to his warnings — a list, he says, that grows every day. “This started as a side project, and right now it’s my full-time job,” he says. “They’re here, they’re hacking us nonstop.”